CVE-2026-78510
massCritical heap buffer overflow in Microsoft Word enables remote code execution
CVE-2026-78510 is a heap-based buffer overflow (CWE-122) in Microsoft Office Word that, per the CVSS vector, is reachable over a network without authentication, without user interaction, and without any special privileges. A memory-corruption condition in Word's processing can be triggered by an attacker who can reach the vulnerable component, causing a heap overflow that disrupts memory layout. Successful exploitation allows the attacker to execute arbitrary code in the context of the Word process, with high impact on confidentiality, integrity, and availability. Organizations running Word within Microsoft 365 Apps or perpetual Office 2016, 2019, 2021, or 2024 are in scope; specific affected build numbers are not stated in the available data and should be taken from Microsoft's advisory. Exploitation status is currently quiet: there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns only a ~1% probability of exploitation within 30 days.
What to do: Inventory endpoints for Microsoft 365 Apps and perpetual Office 2016/2019/2021/2024 installations and apply Microsoft's Word security updates for all affected versions as soon as they are published, prioritizing internet-reachable or document-processing-heavy systems given the network-exploitable, no-authentication CVSS vector. Until patched, verify that Office automatic updates are enabled and consider limiting exposure for high-risk hosts. Because there is no public PoC or known exploitation, treat this as high-priority patching rather than an active-incident response, and re-check KEV/EPSS for movement.
| Microsoft 365 Apps | — |
| Microsoft 365 | — |
| microsoft Office 2016 | — |
| microsoft Office 2019 | — |
| microsoft Office 2021 | — |
| microsoft Office 2024 | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- 365 apps, microsoft 365, office 2016, office 2019, office 2021, office 2024
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.